[{"name":"random","description":"DRBG-derived random bytes (base64), anonymous and rate-limited. Capped at 64 bytes/request; powers the public dice player.","method":"GET","path":"/random","auth":"none","input_schema":{"type":"object","properties":{"bytes":{"type":"integer","minimum":1,"maximum":64,"default":32}}},"output_schema":{"properties":{"bytes":{"title":"Bytes","type":"integer"},"format":{"const":"base64","title":"Format","type":"string"},"data":{"title":"Data","type":"string"}},"required":["bytes","format","data"],"title":"RandomResponse","type":"object"}},{"name":"dice","description":"Rejection-sampled dice rolls (no modulo bias), anonymous and rate-limited. Echoes the DRBG bytes drawn for transparency.","method":"POST","path":"/dice","auth":"none","input_schema":{"properties":{"sides":{"default":6,"maximum":100,"minimum":2,"title":"Sides","type":"integer"},"count":{"default":1,"maximum":6,"minimum":1,"title":"Count","type":"integer"}},"title":"DiceRequest","type":"object"},"output_schema":{"properties":{"sides":{"title":"Sides","type":"integer"},"count":{"title":"Count","type":"integer"},"rolls":{"items":{"type":"integer"},"title":"Rolls","type":"array"},"format":{"const":"base64","title":"Format","type":"string"},"bytes_used":{"title":"Bytes Used","type":"string"},"bytes_count":{"title":"Bytes Count","type":"integer"}},"required":["sides","count","rolls","format","bytes_used","bytes_count"],"title":"DiceResponse","type":"object"}},{"name":"random_bytes","description":"Canonical developer endpoint: DRBG-derived bytes in hex or base64 with a signed provenance receipt. Requires X-API-Key; 32..4096 bytes; per-key rate limit + daily quota.","method":"GET","path":"/v1/random/bytes","auth":"api_key","input_schema":{"type":"object","properties":{"size":{"type":"integer","minimum":32,"maximum":4096},"format":{"type":"string","enum":["hex","base64"],"default":"hex"}},"required":["size"]},"output_schema":{"properties":{"request_id":{"title":"Request Id","type":"string"},"format":{"enum":["hex","base64"],"title":"Format","type":"string"},"data":{"title":"Data","type":"string"},"entropy_epoch":{"title":"Entropy Epoch","type":"integer"},"timestamp":{"format":"date-time","title":"Timestamp","type":"string"},"receipt":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Receipt"}},"required":["request_id","format","data","entropy_epoch","timestamp"],"title":"V1RandomBytesResponse","type":"object"},"quota_note":"daily quota charged equals the number of bytes requested (size)"},{"name":"verify","description":"Verify the provenance of an issued value from its request_id and/or receipt. Provenance only -- never a value-confirmation oracle. Anonymous, rate-limited.","method":"POST","path":"/v1/verify","auth":"none","input_schema":{"properties":{"request_id":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Request Id"},"receipt":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Receipt"}},"title":"VerifyRequest","type":"object"},"output_schema":{"properties":{"request_id":{"anyOf":[{"type":"string"},{"type":"null"}],"title":"Request Id"},"verified":{"title":"Verified","type":"boolean"},"provenance":{"anyOf":[{"additionalProperties":true,"type":"object"},{"type":"null"}],"title":"Provenance"},"note":{"title":"Note","type":"string"}},"required":["request_id","verified","provenance","note"],"title":"VerifyResponse","type":"object"}},{"name":"kem_keypair","description":"Generate an ML-KEM-768 (Kyber, post-quantum) keypair seeded from the QRNG->DRBG chain. Public key always returned; secret key only for the demo flow (loud demo-only note). Requires X-API-Key.","method":"POST","path":"/v1/kem/keypair","auth":"api_key","input_schema":{"properties":{"include_secret_key":{"default":false,"title":"Include Secret Key","type":"boolean"}},"title":"KemKeypairRequest","type":"object"},"output_schema":{"properties":{"request_id":{"title":"Request Id","type":"string"},"algorithm":{"const":"ML-KEM-768","title":"Algorithm","type":"string"},"format":{"const":"base64","title":"Format","type":"string"},"public_key":{"title":"Public Key","type":"string"},"secret_key":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Secret Key"},"entropy_epoch":{"title":"Entropy Epoch","type":"integer"},"timestamp":{"format":"date-time","title":"Timestamp","type":"string"},"receipt":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Receipt"},"note":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Note"}},"required":["request_id","algorithm","format","public_key","entropy_epoch","timestamp"],"title":"KemKeypairResponse","type":"object"},"quota_cost":64},{"name":"kem_encapsulate","description":"Encapsulate against a supplied ML-KEM-768 public key to produce a ciphertext (and, for the demo, the shared secret). Requires X-API-Key.","method":"POST","path":"/v1/kem/encapsulate","auth":"api_key","input_schema":{"properties":{"public_key":{"title":"Public Key","type":"string"},"include_shared_secret":{"default":false,"title":"Include Shared Secret","type":"boolean"}},"required":["public_key"],"title":"KemEncapsulateRequest","type":"object"},"output_schema":{"properties":{"request_id":{"title":"Request Id","type":"string"},"algorithm":{"const":"ML-KEM-768","title":"Algorithm","type":"string"},"format":{"const":"base64","title":"Format","type":"string"},"ciphertext":{"title":"Ciphertext","type":"string"},"shared_secret":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Shared Secret"},"demo_key":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Demo Key"},"entropy_epoch":{"title":"Entropy Epoch","type":"integer"},"timestamp":{"format":"date-time","title":"Timestamp","type":"string"},"receipt":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Receipt"},"note":{"anyOf":[{"type":"string"},{"type":"null"}],"default":null,"title":"Note"}},"required":["request_id","algorithm","format","ciphertext","entropy_epoch","timestamp"],"title":"KemEncapsulateResponse","type":"object"},"quota_cost":32}]